China-nexus advanced persistent threat Weaver Ant has compromised a major Asian telecommunications services provider's network with web shells and various payloads for more than four years as part of its cyberespionage efforts, according to Security Affairs.
Attacks by Weaver Ant involved the deployment of an encrypted China Chopper web shell variant on the organization's internal server followed by the distribution of other webshells, including the nascent INMemory web shell, which enabled in-memory execution of nefarious modules to circumvent forensic detection, a report from Sygnia revealed. Aside from using a recursive HTTP tunnel tool for lateral movement, Weaver Ant also executed PowerShell commands and leveraged Zyxel routers to conceal malicious activity. "The primary objective was to enumerate the compromised Active Directory environment to identify high-privilege accounts and critical servers and add them to their target bank," said Sygnia researchers, who associated the APT with China based on its usage of Zyxel routers, previously Chinese threat actor-linked backdoors, and operating hours.
The implant, identified by Rapid7 Labs with medium confidence as originating from North Korean state-sponsored actors, targets entities in South Korea's automotive and media sectors.
Breeze Comet gains initial access through password spraying and social engineering tactics, impersonating IT support to trick victims into installing Remote Monitoring and Management (RMM) tools like AnyDesk or PowerShell scripts.
Originally reported on by DomainTools and GBHackers, the documents detail a force-generation mechanism for General Staff components, including the GRU and the 8th Directorate, which handles protected communications and information security.